CVE-2026-2441 is a reported (but as yet unconfirmed in MITRE/NVD) zero-day vulnerability in Chrome's CSS parsing engine. It exploits the interaction between CSS `@property` registration and `paint()` worklet initialization to trigger a use-after-free condition on the compositor thread, potentially enabling a sandbox escape from
•23m read time• From sitepoint.com
Table of contents
What Is CVE-2026-2441?Table of ContentsUnderstanding the Attack Surface: How CSS Gained Execution CapabilitiesCVE-2026-2441: Technical Anatomy of the ExploitWho Is Vulnerable: Assessing Your ExposureMitigation: CSP Configuration Template That Blocks CVE-2026-2441Detection: Script to Identify Vulnerable DeploymentsBroader Implications: What This Means for CSS Security Going ForwardYour Action ChecklistSort: